Linux Kernel VFIO/PPCI BAR Resource Check Vulnerability in DMABUF Exports

Vulnerability

A vulnerability in the Linux kernel's VFIO/PPCI subsystem allows DMABUF exports to access unreserved BAR resources. This issue arises because, although these resources are requested at startup, there is no verification that they have been properly reserved before export. The vulnerability can be exploited by accessing unreserved resources through the DMABUF export, potentially leading to unauthorized access or manipulation of memory-mapped I/O regions.

Impact

Exploitation of this vulnerability could result in unauthorized access to unreserved BAR resources, allowing for potential manipulation or interference with device operations that rely on these resources.

Remediation

Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability. Instructions for downloading the patched version can be found in the Linux kernel documentation.

Added: Jul 19, 2026, 6:17 PM
Updated: Jul 19, 2026, 6:17 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
1.3
exploitability
3.5
remediation
7.7
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.